Malicious RTF — malware analysis report

Static analysis result for SHA-256 84c4d1cd6f546956…

MALICIOUS

RTF

582.5 KB
MD5: d850d3323b07c79ec9ea8c913b28f44a SHA-1: d327dcab3ae1c7cdd72f6714a16b8c15e9f018cf SHA-256: 84c4d1cd6f546956619cc7cb0023720735809ba91bf5e4cec32f2807e6d2828e
122 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File

The RTF file contains an embedded OLE object that decodes to a PE file, indicating a likely exploit targeting the Equation Editor. The presence of ".objupdate" suggests that the OLE object is designed to be activated automatically. The decoded artifact, objdata_00_off00000064.bin, is the primary IOC. No scripts were extracted, but the heuristics strongly suggest a classic Equation Editor exploit chain.

Heuristics 4

  • Decoded Equation Editor payload + PE critical RTF_EQUATION_EDITOR
    RTF decodes to an Equation Editor ProgID adjacent to OLE activation and the same decoded object stream contains embedded PE bytes. This matches the Equation Editor exploit surface used by CVE-2017-11882 / CVE-2018-0802 documents, while requiring payload evidence to avoid flagging benign Equation references.
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 1 \objdata section(s) — embedded OLE objects
  • Suspicious extracted artifact info EXTRACTED_FILE_STATIC_TRIAGE
    One or more files extracted from inside this sample matched static suspicious-content checks such as script obfuscation, encoded payload blobs, packed data, or execution/download terms.

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00000064.bin
db7e4de0851044cc15dbf9010e4e20945840a51b6150b379e9a09fc005523566
rtf-objdata-decoded RTF \objdata at offset 0x64 298096 bytes
Detection
ClamAV: No threats found
Obfuscation or payload: likely
Carved artifact entropy is 7.99, consistent with packed or encrypted content.